Senior Software Engineer - Infrastructure Security
New
Q
QuoraInfrastructure security
This position can be performed remotely from anywhere in Canada or the United States., Availability for meetings and impromptu communication during Quora's coordination hours (Mon-Fri: 9am-3pm Pacific Time).Full-TimeSenior
SalaryUS candidates only: For US based applicants, the salary range is $172,279 - $249,640 USD + equity + benefits. Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $221,209 - $256,433 CAD + equity + benefits. For all other locations in Canada, the salary range is $206,461 - $239,337 CAD + equity + benefits.
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSKubernetesCI/CDTerraformCloudFormation
Requirements
- Have capable software engineering skills and expertise in at least one relevant security domain.
- For cloud infrastructure security: have hands-on experience securing large-scale cloud environments, particularly AWS.
- Understand IAM policies, network segmentation, VPC design, and monitoring and logging in cloud-native environments.
- Have experience identifying misconfigurations, mitigating risks, and driving remediation processes.
- For security automation: be skilled at automating security processes and integrating security tools into CI/CD pipelines.
- Have experience with SAST, DAST, and dependency scanning tools and workflows.
- For Linux/system security: understand container security, POSIX Capabilities, SECCOMP, and Linux Security Modules.
- Be able to prioritize critical issues, adapt solutions to the problem, and manage work through obstacles.
- Be able to communicate a vision to peers and management.
- Be available for meetings and impromptu communication during coordination hours, Monday through Friday, 9am-3pm Pacific Time.
Responsibilities
- Partner with engineering teams to review cloud and compute architecture design changes.
- Establish threat models for cloud and compute paved roads to identify security risks.
- Develop or adopt open-source tools to monitor and harden cloud infrastructure and operating systems.
- Develop security logging pipelines and detect intrusions.
- Apply AWS and Kubernetes security best practices to inform remediations and the team's control roadmap.
- Drive the definition and implementation of security policies and monitor conformance.
- Write automation code for threat detection, incident containment, and network access management.
- Conduct initial incident triage, determine scope, urgency, and potential impact, and participate in incident response.
View Full Description & ApplyYou'll be redirected to the employer's site